https://seclists.org/oss-sec/2026/q2/758: CVE-2026-46605: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incomplete authorization during destination moval
Published May 31, 2026
·Updated
Affected Software
3 affected components
maven/org.apache.activemq/activemq-broker<5.19.7, >=6.0.0<6.2.6
maven/org.apache.activemq/activemq-all<5.19.7, >=6.0.0<6.2.6
maven/org.apache.activemq/apache-activemq<5.19.7, >=6.0.0<6.2.6
Frequently Asked Questions
1
What is the severity of CVE-2026-46605?
The severity of CVE-2026-46605 is rated as moderate.
2
What versions are affected by CVE-2026-46605?
CVE-2026-46605 affects Apache ActiveMQ Broker versions before 5.19.7 and 6.0.0 before 6.2.6, as well as Apache ActiveMQ All versions before 5.19.7.
3
How do I fix CVE-2026-46605?
To fix CVE-2026-46605, upgrade Apache ActiveMQ Broker to version 5.19.7 or higher and Apache ActiveMQ All to version 5.19.7 or higher.
4
What type of vulnerability is CVE-2026-46605?
CVE-2026-46605 is an incomplete authorization vulnerability during destination moval in Apache ActiveMQ.
5
When was CVE-2026-46605 published?
CVE-2026-46605 was published on May 31, 2026.